Privacy Policy
Draft · last updated 18 August 2026
This policy describes what we collect, why, who else sees it, and what you can ask us to do about it. It is written to be read, not to be survived.
1. Who is responsible
The data controller is Sistemik SpA (RUT 78.493.576-0), Santiago, Chile. Privacy contact: hello@aeviamodeler.ai.
2. What we collect
Account data. Your email address, a hashed password, your display name if you set one, and your plan and subscription status. We need this to give you an account.
Content you create. Your chats, product systems, assessments, comparisons, analyses, reports, workspaces, and any documents you upload to your knowledge base. We store this so the Service works; it is yours.
Connection details. If you connect your own openLCA, we store the connection's name and network details and, for a tunnelled connection, an authentication token for the connector app. We do not store a copy of your database.
Usage and cost records. Per-request records of model, token counts and cost, so we can meter credits and show you what a conversation spent. These are tied to your account.
Technical logs. IP address, user agent, request identifiers, timestamps and errors. Used for security, abuse prevention and debugging.
Payment data. Handled by Paddle, not by us. We receive a transaction reference, the amount, and your subscription status. We never see or store your card details.
We do not use advertising trackers, and there is no third-party analytics or advertising cookie on this website.
3. Why we may process it, lawfully
- To perform our contract with you — running the Service, your account, and billing.
- Our legitimate interests — keeping the Service secure, preventing abuse and fraud, and improving reliability, balanced against your rights.
- Legal obligation — tax and accounting records.
- Consent — where we ask for it, such as optional product email. You can withdraw it at any time.
4. Who else processes it
To operate, we send parts of a request to service providers acting on our instructions. Each receives only what its task requires.
- Large-language-model providers — Anthropic, OpenAI, Google and other model providers we route to. They receive the conversation content needed to generate a response, which can include the LCA entity names and figures under discussion. Our agreements with them prohibit using your content to train their models.
- Web-search provider — receives your search query when you use the assistant's web search.
- Paddle — payment processing and merchant of record; receives what it needs to take payment and issue an invoice.
- Email provider — receives your address to deliver verification, password-reset and account mail.
- Hosting provider — [Hetzner, Germany], where the application and database run.
We do not sell personal data, and we do not share it for advertising. We may disclose data where legally required, and will tell you unless prohibited.
5. Where your data lives, and transfers
The application and its database are hosted in [Germany (EU)]. Some providers above process data elsewhere, including the United States. Where a transfer leaves the EEA we rely on the European Commission's Standard Contractual Clauses or an equivalent safeguard.
6. How long we keep it
- Account and content — while your account exists. Delete your account and we delete them, except as below.
- Backups — deleted content persists in encrypted backups for up to [30 days] before being overwritten.
- Billing records — retained as long as tax law requires, typically [6 years].
- Technical logs — [90 days].
- Signup-credit records — we keep a minimal record that an account received its one-time credit, so it cannot be claimed repeatedly. This survives account deletion by necessity.
7. Your rights
Depending on where you live you may have the right to access, correct, delete, restrict or object to our processing of your personal data, and to receive it in a portable format. Chilean law (Ley 19.628, as amended) and, where it applies to you, the GDPR both give rights of this kind.
To exercise any of them, write to hello@aeviamodeler.ai. We will respond within 30 days. You can also complain to your local data-protection authority.
8. Security
Traffic is encrypted in transit with TLS. Passwords are hashed, never stored in a readable form. Credentials you give us for a third-party service — provider API keys, engine connections — are encrypted at rest. Access to production data is limited to those who need it to operate the Service. Databases are backed up encrypted.
No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant authority as the law requires.
9. Cookies
The application uses cookies and local storage strictly to keep you signed in and to remember interface preferences. There are no advertising or cross-site-tracking cookies, and this marketing website sets no cookies at all.
10. Children
The Service is not directed at children and is not for anyone under 18. We do not knowingly collect their data; if we learn we have, we delete it.
11. Changes
We may update this policy. Material changes are announced by email at least 30 days ahead. The date at the top always reflects the current version.